Thanks for workgrounds. It is very tiresome that this functionality has been working fine in dnsmasq for years, but in Mikrotik it is not. It would be great if someone make bugreport to support.
DoH configuration example. Cacert.pem is CA certificates extracted from Mozilla . /ip dns set servers=1.1.1.1,1.0.0.1 /system ntp client set enabled=yes server-dns-names=time.cloudflare.com /tool fetch url=https://curl.haxx.se/ca/cacert.pem /certificate import file-name=cacert.pem passphrase="&...